NIS2 and the Dutch Cybersecurity Act: what Limburg SMEs need to know now
The Cybersecurity Act has cleared the lower house and awaits the Senate. Most SMEs are not directly in scope, but their largest customers will pull them in anyway. Here is what to sort out now.
By Limburg Cyber Group
The Dutch Cybersecurity Act (Cyberbeveiligingswet, or Cbw), the Netherlands’ implementation of the EU NIS2 Directive, is on its way. For many business owners in Limburg it raises a single question: “Does this apply to me?” The short answer: maybe not directly, but probably through your biggest customers. Below is where things stand at the end of June 2026, without the noise, plus what you can actually do.
Where the law stands now
The Dutch House of Representatives (Tweede Kamer) passed the Cybersecurity Act on 15 April 2026, after which the bill moved to the Senate (Eerste Kamer). The Senate’s plenary debate is scheduled for early July 2026, jointly with the Critical Entities Resilience Act.
One thing to be clear about: the law is not yet in force. Earlier in the spring, “1 July 2026” was widely cited as the start date, but the pace of the parliamentary process has overtaken it. A definitive entry-into-force date will only follow once the Senate has approved the bill. Until then, the Cbw imposes no obligations. The direction of travel is clear: adoption is widely expected, so preparing is sensible, just not by panicking over a date that is not yet fixed.
Is my company directly in scope?
Whether you fall directly under the law depends on two things at once: your sector and your size. The law targets organisations designated as “essential” or “important” within a set of named sectors: energy, transport, healthcare, digital infrastructure, food, chemicals, and waste and water management, among others. As a rule of thumb, a threshold of around 50 employees or more than 10 million euros in turnover applies.
For the typical Limburg SME, that often means you are not directly in scope. And that is exactly where most owners mistakenly stop reading.
The real reason to start now: supply-chain responsibility
NIS2 requires organisations that are in scope to verify and monitor the cybersecurity of their suppliers in a demonstrable way. This is known as supply-chain responsibility (ketenverantwoordelijkheid). A large, in-scope company will no longer be able to do business freely with a supplier whose digital security is not in order.
For Limburg SMEs, that is where the impact lands. Do you supply a chemicals company at Chemelot, a logistics operator around Venlo, a manufacturer, or a healthcare provider? Then there is a strong chance that customer will, before long, ask you to prove your security is sound, through a questionnaire, contractual requirements, or an audit. Not because the law obliges you directly, but because your customer has to meet its own obligation. A supplier who cannot provide that proof risks losing the contract to a competitor who can.
What you can do right now
You do not need the exact entry date to take sensible steps. Four things worth doing now:
- Map your position in the chain. List your largest customers and check whether they are likely in scope. If they are, the question is coming to you, not the other way around.
- Get the basics in order. Multifactor authentication, a working backup-and-recovery process, timely patching, and a clear picture of who has access to what. These are not exotic measures; they are the items that appear on nearly every supplier questionnaire.
- Write it down. Verification is about being able to demonstrate. A measure you take but do not document does not count for a customer or a regulator.
- Make cybersecurity a board-level matter. Under NIS2, digital security becomes an explicit leadership responsibility, with potential personal liability for directors in cases of demonstrable negligence. Delegating it to “IT” is not cover.
Where Limburg Cyber Group helps
We help Limburg SMEs work out exactly that position and get the basics demonstrably in order, before the first supplier questionnaire lands. Our NIS2 readiness scan maps where you stand against the requirements your customers will impose, and which steps to prioritise.
Want to know whether and how NIS2 reaches your business? Get in touch for a no-obligation conversation.
Read more
GDPR and NIS2: where they overlap and where they differ
GDPR and NIS2 look alike, but protect different things. Here is how to understand the overlap, the differences, and why you may face both at once.
ISO 27001 vs NIS2: what is the difference and do you need both?
ISO 27001 and NIS2 are often mentioned in one breath, but they are not the same. The difference explained clearly, and how they actually reinforce each other.
NIS2 and director liability: why this is a boardroom topic
Under NIS2, directors are personally responsible for cybersecurity. What that means concretely and how the board can demonstrably take up its role.